Executive brief
A security vulnerability exists in the Windows kernel component responsible for graphics processing. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software.
Technical details
A use-after-free (UAF) vulnerability exists within the Win32K GRFX component of the Windows kernel. The flaw is triggered when the system improperly handles objects in memory, allowing an attacker to reference memory after it has been freed. To exploit this, an attacker must have local access to the system and be authenticated with low privileges. Successful exploitation enables the attacker to execute code with elevated privileges, potentially gaining SYSTEM-level access. The attack complexity is rated as high, suggesting specific timing or system states are required to trigger the bug.
Affected products
- Microsoft Windows Not specified
Timeline
- 2026-05-12: disclosed: Initial publication of the vulnerability details.
- 2026-05-12: advisory: Microsoft released an advisory and update guide.